Easy Textillate
Easy Textillate has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.
2 independent researchers contributed these findings, one record each. Easy Textillate is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-32526Easy Textillate <= 2.02 - Authenticated(Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Easy Textillate
Author
Flector
The plugin allows you to add animation to any text using shortcodes in posts, pages or site widgets. You can also use PHP code to add text animations directly in theme files. The plugin fully utilizes the capabilities of the Textillate.js script and is very easy to use – you don’t need to spend time including scripts and style files. Just create a shortcode with the necessary animation and paste it into your post. Easy Textillate uses the following libraries: textillate.js by Jordan Schroter animate.css by Daniel Eden lettering.js by Dave Rupert If you liked my plugin, please rate it.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C